ATT&CKReferencesMicrosoft Deep Dive Solorigate January 2021

Microsoft Deep Dive Solorigate January 2021

MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples34

TechniqueUsed byProcedure example
T1003.006
DCSync
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers.

T1012
Query Registry
MalwareTEARDROP

TEARDROP checked that HKU\SOFTWARE\Microsoft\CTF existed before decoding its embedded payload.

T1018
Remote System Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used AdFind to enumerate remote systems.

T1027
Obfuscated Files or Information
MalwareTEARDROP

TEARDROP created and read from a file with a fake JPG header, and its payload was encrypted with a simple rotating XOR cipher.

T1027.002
Software Packing
MalwareRaindrop

Raindrop used a custom packer for its Cobalt Strike payload, which was compressed using the LZMA algorithm.

T1027.013
Encrypted/Encoded File
MalwareRaindrop

Raindrop encrypted its payload using a simple XOR algorithm with a single-byte key.

T1036
Masquerading
MalwareRaindrop

Raindrop was built to include a modified version of 7-Zip source code (including associated export names) and Far Manager source code.

T1036.005
Match Legitimate Resource Name or Location
MalwareSUNBURST

SUNBURST created VBScripts that were named after existing services or folders to blend into legitimate activities.

T1036.005
Match Legitimate Resource Name or Location
MalwareRaindrop

Raindrop was installed under names that resembled legitimate Windows file and directory names.

T1036.005
Match Legitimate Resource Name or Location
MalwareTEARDROP

TEARDROP files had names that resembled legitimate Window file and directory names.

T1047
Windows Management Instrumentation
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used WMI for the remote execution of files for lateral movement.

T1057
Process Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes.

T1059.005
Visual Basic
MalwareSUNBURST

SUNBURST used VBScripts to initiate the execution of payloads.

T1070
Indicator Removal
MalwareSUNBURST

SUNBURST removed HTTP proxy registry values to clean up traces of execution.

T1070.006
Timestomp
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 modified timestamps of backdoors to match legitimate Windows files.

T1070.007
Clear Network Connection History and Configurations
MalwareSUNBURST

SUNBURST also removed the firewall rules it created during execution.

T1070.009
Clear Persistence
MalwareSUNBURST

SUNBURST removed IFEO registry values to clean up traces of persistence.

T1112
Modify Registry
MalwareSUNBURST

SUNBURST had commands that allow an attacker to write or delete registry keys, and was observed stopping services by setting their HKLM\SYSTEM\CurrentControlSet\services\\[service_name]\\Start registry entries to value 4. It also deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.

T1140
Deobfuscate/Decode Files or Information
MalwareRaindrop

Raindrop decrypted its Cobalt Strike payload using an AES-256 encryption algorithm in CBC mode with a unique key per sample.

T1140
Deobfuscate/Decode Files or Information
MalwareTEARDROP

TEARDROP was decoded using a custom rolling XOR algorithm to execute a customized Cobalt Strike payload.

T1195.002
Compromise Software Supply Chain
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software.

T1218.011
Rundll32
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `Rundll32.exe` to execute payloads.

T1218.011
Rundll32
MalwareSUNBURST

SUNBURST used Rundll32 to execute payloads.

T1482
Domain Trust Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains.

T1546.003
Windows Management Instrumentation Event Subscription
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used a WMI event filter to invoke a command-line event consumer at system boot time to launch a backdoor with `rundll32.exe`.

T1546.012
Image File Execution Options Injection
MalwareSUNBURST

SUNBURST created an Image File Execution Options (IFEO) Debugger registry value for the process dllhost.exe to trigger the installation of Cobalt Strike.

T1555
Credentials from Password Stores
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used account credentials they obtained to attempt access to Group Managed Service Account (gMSA) passwords.

T1558.003
Kerberoasting
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained Ticket Granting Service (TGS) tickets for Active Directory Service Principle Names to crack offline.

T1560.001
Archive via Utility
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives.

T1587.001
Malware
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 used numerous pieces of malware that were likely developed for or by the group, including SUNBURST, SUNSPOT, Raindrop, and TEARDROP.

T1680
Local Storage Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `fsutil` to check available free space before executing actions that might create large files on disk.

T1685
Disable or Modify Tools
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the service control manager on a remote system to disable services associated with security monitoring products.

T1685.001
Disable or Modify Windows Event Log
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29, used `AUDITPOL` to prevent the collection of audit logs.

T1686
Disable or Modify System Firewall
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `netsh` to configure firewall rules that limited certain UDP outbound packets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.